nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-23857 CVE-2021-23857
CRITICAL
Login with hash
Record summary
CVE-2021-23857 has a selected CVSS score of 10.0 (critical).
Description
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
IndraMotion MLC L20, L40Browse Rexroth / IndraMotion MLC L20, L40 | CVE List | 12 VRS | affected |
IndraMotion MLC L25, L45, L65, L75, L85, XM21, XM22, XM41 and XM42 IndraMotion XLCBrowse Rexroth / IndraMotion MLC L25, L45, L65, L75, L85, XM21, XM22, XM41 and XM42 IndraMotion XLC | CVE List | 12 VRS | affected |
References
2psirt.bosch.comConfirmation
https://psirt.bosch.com/security-advisories/bosch-sa-741752.html